Data Processing Agreement
Last updated: 28 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Any Number Anywhere and the Customer. A printable supplier-pack version is available on request from support@anynumberanywhere.com.
1. Parties and roles
This DPA is entered into between:
- Processor:Andrew Sykes, trading as Any Number Anywhere ("Any Number Anywhere", "we", "us"), a sole trader based in the United Kingdom. Contact: support@anynumberanywhere.com.
- Controller:the customer entity or individual that accepts the Terms of Service and uses the Service ("Customer", "you").
For Customer Data (defined below), the Customer is the controller and Any Number Anywhere is the processor under the UK GDPR and the Data Protection Act 2018. For Account Data relating to the Customer's own account, billing, and our operation of the Service, Any Number Anywhere acts as an independent controller, as described in our Privacy Policy.
2. Incorporation and precedence
This DPA is incorporated into, and forms part of, the Terms of Service. By creating an account, completing checkout, or otherwise accepting the Terms, the Customer agrees to this DPA. If there is a conflict between this DPA and the Terms or Privacy Policy on a data-protection matter relating to Customer Data, this DPA prevails.
3. Definitions
- Applicable Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (as amended), and any other applicable UK data protection or electronic communications law.
- Customer Data means personal data processed by Any Number Anywhere on behalf of the Customer in providing the Service, including call content and metadata, SMS content and metadata, voicemails, call recordings, transcripts, AI Receptionist conversation data, caller contact details captured through the Service, and similar communications content configured or generated through the Customer's account.
- Account Data means personal data relating to the Customer as a user of the Service (for example account credentials, billing records, and support correspondence) that Any Number Anywhere processes as an independent controller.
- Sub-processor means a third party engaged by Any Number Anywhere to process Customer Data in connection with the Service.
- Service means the Any Number Anywhere VoIP, SMS, voicemail, dashboard, and AI Receptionist services described in the Terms.
- Terms such as controller, processor, personal data, processing, data subject, and personal data breach have the meanings given in Applicable Data Protection Law.
4. Scope of processing
The subject matter, nature, purpose, duration, types of personal data, and categories of data subjects are set out in Schedule 1. Any Number Anywhere will process Customer Data only to provide, maintain, secure, and support the Service, and only on the Customer's documented instructions.
The Customer's documented instructions are: (a) this DPA; (b) the Terms; (c) the Customer's configuration of the Service (including enabling or disabling call recording, transcription, AI summaries, AI Receptionist, calendar booking, and similar features); and (d) other reasonable written instructions that are consistent with the Service.
If Applicable Data Protection Law requires Any Number Anywhere to process Customer Data other than on the Customer's instructions, we will inform the Customer before doing so where legally permitted.
5. Customer responsibilities
The Customer warrants and undertakes that:
- it is entitled to provide Customer Data to Any Number Anywhere for processing as contemplated by the Service;
- it has a lawful basis under Applicable Data Protection Law for that processing, and has provided any required notices to data subjects (including callers);
- its instructions are lawful;
- it will configure optional features (including call recording, AI transcription/summaries, and AI Receptionist) appropriately for its use case; and
- where the Service may process confidential, employment, health, or other special-category or sensitive information (for example HR consultancy calls), the Customer remains solely responsible for deciding whether and how to use the Service for that content and for complying with any additional legal requirements.
6. Processor obligations
Any Number Anywhere shall:
- process Customer Data only on documented instructions from the Customer, unless required to do otherwise by Applicable Data Protection Law;
- ensure that persons authorised to process Customer Data are bound by confidentiality obligations;
- implement appropriate technical and organisational measures as described in Schedule 3;
- comply with the sub-processing and transfer rules in Sections 7 and 8;
- taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, with responding to data subject requests under Applicable Data Protection Law;
- assist the Customer in ensuring compliance with obligations under Articles 32 to 36 UK GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and information available to us;
- at the Customer's choice, delete or return Customer Data after the end of the provision of Services relating to processing, and delete existing copies unless Applicable Data Protection Law requires storage; and
- make available to the Customer information necessary to demonstrate compliance with this DPA and Article 28 UK GDPR, and allow for and contribute to audits as set out in Section 11.
7. Sub-processors
The Customer authorises Any Number Anywhere to engage the Sub-processors listed in Schedule 2 (and any replacements notified under this Section) to process Customer Data as needed to provide the Service.
We will impose data-protection obligations on each Sub-processor that are no less protective, in substance, than those in this DPA. We remain responsible to the Customer for each Sub-processor's performance of its obligations in respect of Customer Data.
We will give the Customer prior notice of any intended addition or replacement of a Sub-processor (including by updating Schedule 2 on this page and, for material changes, by email to the Customer's account email where practicable). The Customer may object on reasonable data-protection grounds within 14 days of notice. If the Customer objects and we cannot reasonably accommodate the objection, either party may terminate the affected Service on written notice without penalty for that objection alone.
8. International transfers
Where Customer Data is transferred outside the United Kingdom, Any Number Anywhere will ensure that an appropriate transfer mechanism under Applicable Data Protection Law is in place (for example, the UK International Data Transfer Agreement / Addendum, adequacy regulations, or another lawful mechanism). Details of Sub-processor locations are summarised in Schedule 2.
9. Security incidents
Any Number Anywhere will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably required for the Customer to meet its breach-notification obligations. Notification of a breach is not an admission of fault or liability.
10. Deletion and return
During the subscription, the Customer may delete certain Customer Data through the Service (for example individual recordings or messages, where that functionality is available). After termination or expiry of the Service, we will delete Customer Data in accordance with our retention practices described in the Privacy Policy, or earlier on written request where reasonably practicable, except for data we must retain under Applicable Data Protection Law or for establishing, exercising, or defending legal claims. Account Data and anonymised or aggregated data that does not identify data subjects may be retained as an independent controller or outside the scope of this DPA.
11. Audits
On reasonable written request, no more than once per year (unless required following a personal data breach or by a competent authority), Any Number Anywhere will provide written information and relevant third-party audit summaries or security documentation reasonably necessary to demonstrate compliance with this DPA. On-site audits are available only where the written information is demonstrably insufficient, on at least 30 days' notice, during business hours, subject to confidentiality, and at the Customer's cost unless the audit reveals a material breach of this DPA by us.
12. Liability and term
Liability under this DPA is subject to the limitations and exclusions in the Terms, except to the extent Applicable Data Protection Law prohibits such limitation. This DPA takes effect on the date the Customer first accepts the Terms (or first uses the Service, if earlier) and continues for as long as Any Number Anywhere processes Customer Data on the Customer's behalf.
13. Governing law
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, without prejudice to either party's right to bring proceedings before the Information Commissioner's Office or another competent supervisory authority.
14. Contact
Andrew Sykes trading as Any Number Anywhere
United Kingdom
Email: support@anynumberanywhere.com
Website: anynumberanywhere.com
Schedule 1 — Description of processing
- Subject matter: provision of UK virtual-number telephony, SMS, voicemail, call recording/transcription (where enabled), web dashboard, and AI Receptionist features.
- Duration: for the term of the Customer's subscription and any post-termination retention period described in the Privacy Policy / this DPA.
- Nature and purpose: transmitting, storing, routing, recording (optional), transcribing (optional), summarising (optional), displaying, and otherwise processing communications and related metadata to deliver the Service configured by the Customer.
- Types of personal data: telephone numbers; names and contact details provided by callers or the Customer; call and SMS content and metadata; voicemail audio and transcripts; call recordings and transcripts (if enabled); AI conversation transcripts and extracted fields (if AI Receptionist enabled); calendar booking details (if enabled); and other content the Customer or callers submit through the Service.
- Special category / sensitive data: the Service is not designed specifically for special-category data, but Customer or caller content may incidentally include it (including in HR, healthcare, or similar contexts). The Customer determines whether to use the Service for such content.
- Categories of data subjects: the Customer's callers, contacts, clients, employees or contractors (where relevant), and other individuals whose data appears in communications processed through the Service.
Schedule 2 — Authorised Sub-processors
Current Sub-processors that may process Customer Data (depending on plan and feature configuration):
| Sub-processor | Purpose | Typical location |
|---|---|---|
| Twilio, Inc. / Twilio UK affiliates | Voice, SMS, number provisioning, call/SMS delivery, optional recording storage | UK / EEA / USA (as required for routing) |
| Supabase, Inc. | Application database, authentication, file storage for Service data | UK / EEA (project region as configured) |
| OpenAI, L.L.C. | AI transcription analysis, summaries, and AI Receptionist conversation intelligence (where enabled); zero-data-retention settings applied where available | USA / processing region per OpenAI |
| ElevenLabs, Inc. | Text-to-speech for AI Receptionist (AI Receptionist plan) | USA / EEA per vendor |
| Deepgram, Inc. | Real-time speech-to-text for AI-handled calls (AI Receptionist plan) | USA / EEA per vendor |
| Apple / Google | Push notification delivery (device tokens and notification payloads) | Global |
| Hosting / edge compute providers used to run Service backends | Running application and edge functions that process Customer Data in transit/at rest as part of the Service | As configured for production workloads (prefer UK/EEA where practicable) |
Payment processors (for example Stripe and RevenueCat) primarily process Account Data / payment data as independent controllers or under separate terms, and are described in the Privacy Policy. Google/Microsoft calendar providers process calendar data under the Customer's connection and the relevant provider terms when calendar booking is enabled.
Schedule 3 — Technical and organisational measures
Taking into account the state of the art, costs, and the nature/scope/context of processing, Any Number Anywhere maintains measures including:
- TLS/HTTPS encryption for data in transit;
- encryption at rest for stored Service data where provided by underlying platforms;
- access controls and authentication for Customer accounts and administrative access;
- least-privilege access to production systems and Customer Data;
- logging and monitoring of core Service components;
- vendor due diligence and contractual data-protection terms with Sub-processors;
- retention limits and deletion tooling consistent with the Privacy Policy; and
- incident response processes for suspected security and personal data breaches.
This DPA is provided to help Customers meet their supplier due-diligence and Article 28 documentation needs. It is not formal legal advice. Customers with specialised requirements (including processing of special-category data at scale) should obtain independent legal advice and may request a signed supplier-pack copy from support@anynumberanywhere.com.